vendor:
GeeCarts
by:
SecurityFocus
7.5
CVSS
HIGH
Remote File-Include and Cross-Site Scripting
79, 80
CWE
Product Name: GeeCarts
Affected Version From: All
Affected Version To: All
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
GeeCarts Multiple Input Validation Vulnerabilities
GeeCarts is prone to multiple input-validation vulnerabilities, including remote file-include and cross-site scripting issues, because it fails to sufficiently sanitize user-supplied data. Exploiting these issues may allow an attacker to compromise the application and the underlying system or execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site; other attacks are also possible.
Mitigation:
Input validation should be used to ensure that untrusted data is not used to execute unintended commands or access data that is not intended to be accessed.